Privacy Policy

Last updated: 8 September 2026

This Privacy Policy describes the processing of personal data carried out in connection with access to and use of Markery, available at markery.whilehaus.net (the "Service"), and forms part of the Terms and Conditions of the Service.

The data controller is Martin Bonafede, Argentine tax ID (CUIT) 20-33215496-7, registered under the simplified tax regime (monotributo), domiciled at Av. Rivadavia 5785, floor 15, apartment 1, City of Buenos Aires (postcode 1406), Republic of Argentina, trading under the business name Whilehaus. Contact address for the purposes of this Policy: hola@whilehaus.net.

The Service does not sell personal data, does not disclose it for advertising purposes and does not use it to train artificial intelligence models.

1. Scope

1.1. This Policy applies to personal data processed through the Service, its public website, its application programming interfaces and its connector for artificial intelligence agents (MCP).

1.2. It does not apply to third-party sites, applications or services that the user accesses from the Service or links to it, which are governed by their own policies.

2. Dual role: controller and processor

2.1. In respect of account data and Service usage data, Whilehaus acts as data controller.

2.2. In respect of third-party personal data that the user uploads to the Service as part of its content, including data of its own clients, contacts or represented parties, the user acts as controller and Whilehaus as processor. In that case, Whilehaus processes such data solely in accordance with the instructions the user gives through use of the Service, does not apply it to unrelated purposes and deletes or returns it upon termination of the relationship, on the terms of section 25 of Argentine Law 25.326.

2.3. The user is responsible for having a sufficient lawful basis to upload third-party personal data to the Service and for informing those third parties where appropriate.

3. Categories of data processed

3.1. Data supplied by the user:

  • Identification and contact data: email address and, where provided, first and last name.
  • Credentials: passwords are stored exclusively by means of a hash function, never in readable form. Where access is effected through Google or GitHub, the account identifier and associated email address are received from the provider.
  • Content uploaded to the Service: documents, brand manuals, briefs, text, images, files, typefaces, colour palettes, content plans and notes, together with any third-party personal data the user chooses to include in them.
  • Organisational data: names of spaces, companies and projects, invited members and assigned roles.
  • Support communications: the content of messages sent to Whilehaus.

3.2. Data generated by use of the Service:

  • Technical and connection data: IP address, user agent, session identifiers, timestamps, access logs and error logs.
  • Usage data: actions performed within the Service, feature usage, consumption against plan limits and the activity of agents authorised through the MCP connector.
  • Subscription data: current plan, subscription status, billing period and identifiers assigned by the payment processor. Complete payment instrument data is not stored.

3.3. Data obtained from third parties: data supplied by federated authentication providers and payment processors, with the scope described above, and data that a member of a space provides when inviting another person.

4. Purposes and lawful bases

  • Provision of the Service: creating and administering the account, hosting and displaying content, operating spaces and permissions. Basis: performance of the contract.
  • Subscription management: activation, collection, renewal, cancellation and issuance of receipts. Basis: performance of the contract and compliance with legal, tax and accounting obligations.
  • Transactional communications: email address verification, password reset, space invitations and notices of material changes. Basis: performance of the contract.
  • Security and integrity: access logs, rate limits, detection and prevention of unauthorised access, abuse and fraud. Basis: legitimate interest.
  • Support and handling of enquiries. Basis: performance of the contract and legitimate interest.
  • Improvement of the Service through aggregated usage metrics and performance statistics. Basis: legitimate interest.
  • Compliance with requirements of competent authorities and the exercise or defence of rights. Basis: compliance with legal obligations and legitimate interest.

4.1. Where legitimate interest is the basis relied upon, it has been assessed that the processing is necessary, proportionate and not detrimental to the reasonable expectations of the data subject.

4.2. No automated decisions are taken that produce legal effects concerning the data subject or otherwise significantly affect them.

5. File storage

5.1. Files uploaded to the Service are held, by default, in the storage infrastructure administered by Whilehaus.

5.2. A user with sufficient permissions may link its own storage account to a space, in particular a Google Drive account. From the moment of linking, files uploaded to that space are held in the linked account, remaining under the user’s control and subject to the relevant provider’s policies.

5.3. All files of a space are accessible to its members through the Service, irrespective of the storage in which they reside. To make this possible, the Service delivers files through its own domain by means of signed links of limited validity, without exposing the storage account credentials and without sharing permissions in it.

5.4. Unlinking a storage account does not delete files already held in it, which remain under the user’s exclusive control.

6. Google API integration and Limited Use

6.1. The Service integrates with Google APIs for three distinct purposes: sign-in with a Google account; where the user so enables, hosting of files in Google Drive; and, where the user links a channel, publication of videos to YouTube through the YouTube API Services.

6.2. The permissions requested and their purpose are as follows:

  • openid and userinfo.email: identification of the account and retrieval of the associated email address, solely in order to establish the session or to identify in the interface the linked storage account or YouTube channel.
  • drive.file: restricted access, limited exclusively to files and folders that the Service itself creates, or that the user deliberately opens with the Service. This permission does not grant access to the remainder of the user’s Google Drive content: Markery cannot read, list, modify or delete files or folders it did not create.
  • youtube (https://www.googleapis.com/auth/youtube): management of the YouTube channel the user links, solely in order to publish and maintain the content the user approves. It covers uploading the video (videos.insert), setting and subsequently updating its details, namely title, description, tags, category, privacy status and scheduled publication date (videos.update), setting the thumbnail (thumbnails.set) and reading the user’s own channel data (channels.list with the mine parameter). No narrower permission is requested because none suffices: youtube.upload authorises the upload but authorises neither videos.update nor reading the channel, so that without the youtube permission the Service could not correct the details of a video already uploaded, nor identify the linked channel.

6.3. Markery’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

6.4. In particular, with respect to data obtained from Google APIs:

  • It is used exclusively to provide and improve the user-facing features of the Service.
  • It is not transferred to third parties, except to the extent strictly necessary to provide those features, where required by law or by a competent authority, or where the user gives express consent.
  • It is not used for advertising purposes, nor disclosed to advertising platforms, data brokers, information resellers or market intelligence providers.
  • It is not read by humans, unless the user gives express consent for a specific support operation, it is necessary for security purposes, including the investigation of abuse or vulnerabilities, or it is required by law.
  • It is not used to train generalised artificial intelligence models.

6.5. Access and refresh credentials issued by Google are stored encrypted using AES-256-GCM and are used solely to operate the Service folder within the linked storage account or the linked YouTube channel, according to the purpose the user has authorised.

6.6. The user may revoke access at any time from the Service itself, in the storage section or the connections section of its settings as applicable, or from its Google account administration at https://myaccount.google.com/permissions or at https://security.google.com/settings/security/permissions. Revocation does not delete files already held in the user’s Google Drive, nor videos already published to the user’s YouTube channel, which remain under the user’s exclusive control.

6.7. The features of the Service that operate on YouTube use the YouTube API Services. By using them, the user agrees to be bound by the YouTube Terms of Service, available at https://www.youtube.com/t/terms. Google’s processing of the information the Service accesses is additionally governed by the Google Privacy Policy, available at https://policies.google.com/privacy.

6.8. On linking a YouTube channel, the Service obtains and stores the following data: the channel identifier, its title, its public handle, its profile image and the email address of the Google account that granted the authorisation, together with the refresh credential issued by Google, which is stored encrypted in accordance with clause 6.5. That credential is retained for as long as the user’s consent subsists and is used solely for the purposes the user authorised. The remaining authorised data obtained from the YouTube API Services, namely the channel metadata listed in this clause, is retained for no more than thirty (30) calendar days, after which it is refreshed against YouTube or deleted. Unlinking the channel results in deletion of the credential and of that metadata. Any request to delete data obtained from YouTube, and any inability to verify that the authorisation granted remains valid, is acted upon within thirty (30) days.

6.9. The video and its details, including title, description, tags, thumbnail, category, privacy status and publication date, are determined by the user. The Service publishes nothing to YouTube that the user has not approved in advance and expressly, and does not alter the values the user sets nor append text of its own to them. Final control over the content that is published rests with the user.

7. Artificial intelligence features

7.1. Where the user employs features assisted by artificial intelligence, the data strictly necessary to execute the requested operation is transmitted to the relevant model provider, which acts as processor or as independent controller depending on the case.

7.2. Where the user supplies its own provider credentials, the information is transmitted directly to the provider it has chosen, under that provider’s terms and privacy policy.

7.3. Whilehaus does not use user content to train artificial intelligence models, whether its own or third parties’, and does not authorise its providers to do so.

8. Authorised agents and MCP connector

8.1. The user may enable access by artificial intelligence agents and third-party applications to the content of a space, by means of access tokens or through the authorisation procedure provided for that purpose.

8.2. Enablement is granted per space and covers only the powers the user selects; write powers require additional and express enablement. The user may review and revoke current authorisations at any time.

8.3. Each agent’s provider processes the information it accesses in accordance with its own policies, which are outside Whilehaus’s control. Operations executed by agents are logged for security and audit purposes.

9. Recipients and processors

9.1. Data is not disclosed to third parties, save for the providers necessary to operate the Service, which act as processors and are contractually bound to process data in accordance with instructions, subject to confidentiality and with adequate security measures:

  • Supabase Inc.: database, authentication and file storage. Infrastructure hosted on Amazon Web Services, region us-west-2 (Oregon, United States).
  • Vercel Inc.: application hosting, content delivery network, application logs and aggregated usage and performance metrics (United States).
  • Google LLC: federated authentication; where the user so enables, file hosting in Google Drive; and, where the user links a channel, publication of videos to YouTube.
  • GitHub, Inc.: federated authentication, where the user opts for it.
  • Resend: transactional email delivery.
  • Mercado Pago: payment processing for the Republic of Argentina.
  • Dodo Payments: payment processing in all other jurisdictions, as Merchant of Record.
  • Anthropic PBC and other artificial intelligence model providers: solely where the user employs features requiring them, with the scope set out in section 7.

9.2. Data may be disclosed to competent administrative or judicial authorities upon a reasoned request, and to professional advisers bound by confidentiality, to the extent necessary for the exercise or defence of rights.

9.3. In the event of corporate reorganisation, merger or transfer of the business unit, data may be transferred to the successor, which will be bound by this Policy. The user will be notified.

10. International transfers

10.1. The Service’s principal infrastructure is hosted in the United States of America. Certain processors may process data in other jurisdictions.

10.2. The United States is not covered by a general adequacy finding under section 12 of Argentine Law 25.326. Transfers therefore rely on the informed consent of the data subject, on the necessity of the transfer for performance of the contract, and on contractual commitments entered into with each processor replicating the protection standards required by Argentine law and, where applicable, by Regulation (EU) 2016/679, by means of standard contractual clauses.

11. Retention periods

  • Account data and content: retained while the account remains active and necessary to provide the Service.
  • Account deletion: data is removed from production systems within thirty (30) calendar days of the request. Encrypted backups may subsist for up to a further ninety (90) days until rotated.
  • Minimal, non-identifying records are retained in order to preserve the integrity of shared spaces and to prevent improper reuse of identifiers.
  • Billing documentation and accounting records: for the period required by Argentine tax and commercial law, which may extend to ten (10) years.
  • Technical and security logs: up to twelve (12) months, unless required for the investigation of an incident.
  • Authorised data obtained from the YouTube API Services: metadata of the linked channel, up to thirty (30) calendar days; refresh credentials, for as long as the user’s consent subsists. All in accordance with clause 6.8.
  • Free accounts inactive for more than twelve (12) months: may be deactivated and deleted, following notice to the registered email address.

11.1. Files held in a user’s own storage account are not deleted by Whilehaus upon deletion of the account, and remain under that user’s exclusive control.

12. Security measures

12.1. Technical and organisational measures appropriate to the risk are applied, including: encryption of communications by means of TLS, encryption of reversible secrets at rest using AES-256-GCM, isolation of data per holder at database level through row-level security policies, storage of passwords by means of a hash function, role-based access control, operation logging and restriction of internal access to the minimum necessary.

12.2. No system is invulnerable. Should a security incident affecting personal data occur, containment measures will be adopted and the notifications required by applicable law will be given to data subjects and to the supervisory authority within the prescribed periods.

13. Cookies and similar technologies

13.1. The Service uses only technically necessary cookies and local storage: the session cookie supporting authentication, the cookie recording the selected language and those preserving interface preferences. Disabling them prevents the Service from functioning.

13.2. The Service displays no advertising, incorporates no advertising or cross-site tracking cookies, and shares no data with advertising platforms.

13.3. Aggregated usage and performance metrics are obtained by means of tools that do not use cookies and do not build individual profiles.

14. Rights of the data subject

14.1. The data subject may exercise the rights of access, rectification, updating, deletion, portability and, where applicable, objection and restriction of processing. Certain rights may be exercised directly from the account settings; the remainder by request to hola@whilehaus.net. Requests are handled within the statutory periods, following reasonable verification of the requester’s identity.

14.2. Where the request concerns data in respect of which Whilehaus acts as processor, it will be referred to the user responsible for that content, to whom it falls to resolve it.

14.3. Under Argentine law, the data subject is entitled to exercise the right of access to their data free of charge at intervals of no less than six months, unless a legitimate interest to the contrary is established, pursuant to section 14, subsection 3 of Law 25.326.

14.4. The Agencia de Acceso a la Información Pública, as the supervisory body under Law 25.326, has the power to hear complaints and claims brought by persons whose rights are affected by non-compliance with the rules in force on personal data protection.

14.5. Data subjects domiciled in the European Economic Area or the United Kingdom additionally hold the rights conferred by Regulation (EU) 2016/679 and by equivalent United Kingdom legislation, including the right to lodge a complaint with the supervisory authority of their jurisdiction. Data subjects domiciled in United States jurisdictions that have enacted privacy legislation hold the rights conferred by that legislation.

15. Minors

15.1. The Service is directed exclusively at persons aged eighteen (18) or over. Data concerning minors is not knowingly collected. Should an account belonging to a minor be identified, it will be deleted together with the associated data.

16. Amendments to this Policy

16.1. This Policy may be updated. Material amendments will be notified to the registered email address or by notice within the Service, with reasonable advance notice of their taking effect. The date of the last update is stated at the beginning of the document.

17. Contact

Enquiries regarding this Policy and the exercise of rights: hola@whilehaus.net. Martin Bonafede (Whilehaus), CUIT 20-33215496-7, Av. Rivadavia 5785, floor 15, apartment 1, City of Buenos Aires (postcode 1406), Republic of Argentina.

This Policy was drafted in English, which is the governing version for all purposes. Translations into other languages are provided for information only: in the event of discrepancy, the English version prevails.